2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21255 | MEDIUM | 5.7 | 0.9% | Mar 2, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-27885 | HIGH | 8.8 | 3.2% | Mar 2, 2021 | usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. |
| CVE-2021-22296 | MEDIUM | 5.5 | 0.2% | Mar 2, 2021 | A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file sys... |
| CVE-2021-22294 | LOW | 3.3 | 0.2% | Mar 2, 2021 | A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may exploit this vulnerabili... |
| CVE-2021-22187 | MEDIUM | 4.3 | 1.0% | Mar 2, 2021 | An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaus... |
| CVE-2021-3384 | MEDIUM | 5.3 | 1.0% | Mar 2, 2021 | A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP table... |
| CVE-2021-25330 | HIGH | 7.5 | 0.4% | Mar 2, 2021 | Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions i... |
| CVE-2021-21514 | MEDIUM | 4.9 | 5.4% | Mar 2, 2021 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote ... |
| CVE-2021-21513 | CRITICAL | 9.8 | 5.7% | Mar 2, 2021 | Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server ... |
| CVE-2021-27904 | MEDIUM | 5.5 | 0.3% | Mar 2, 2021 | An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, th... |
| CVE-2021-27901 | MEDIUM | 6.8 | 0.1% | Mar 2, 2021 | An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because... |
| CVE-2021-21322 | CRITICAL | 9.8 | 1.9% | Mar 2, 2021 | fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with h... |
| CVE-2021-21321 | CRITICAL | 10 | 1.8% | Mar 2, 2021 | fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In... |
| CVE-2021-21320 | MEDIUM | 4.3 | 0.9% | Mar 2, 2021 | matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0... |
| CVE-2021-27730 | CRITICAL | 9.8 | 1.4% | Mar 2, 2021 | Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. Th... |
| CVE-2021-27888 | MEDIUM | 6.1 | 0.6% | Mar 2, 2021 | ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters. |
| CVE-2021-27804 | CRITICAL | 9.8 | 4.0% | Mar 2, 2021 | JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption. |
| CVE-2021-27731 | MEDIUM | 6.1 | 0.7% | Mar 2, 2021 | Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed ve... |
| CVE-2021-25309 | CRITICAL | 9.8 | 1.3% | Mar 2, 2021 | The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout... |
| CVE-2021-25306 | HIGH | 7.5 | 1.5% | Mar 2, 2021 | A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers... |
| CVE-2021-27886 | CRITICAL | 9.8 | 45.6% | Mar 2, 2021 | rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metachara... |
| CVE-2021-27884 | MEDIUM | 5.1 | 0.3% | Mar 1, 2021 | Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tok... |
| CVE-2021-3342 | CRITICAL | 9.8 | 4.2% | Mar 1, 2021 | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a... |
| CVE-2021-27878 | HIGH | 8.8 | 24.0% | Mar 1, 2021 | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc... |
| CVE-2021-27877 | CRITICAL | 9.8 | 64.9% | Mar 1, 2021 | An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now